Skip to main content

Cookie Policy

Version: 1.0

Last Revised: April 2026


Important Notice — Please Read Carefully​

This Cookie Policy (the "Cookie Policy" or "Policy") explains how Overlayer Labs Ltd, a business company incorporated under the laws of the British Virgin Islands (the "Controller", "Overlayer Labs", "we", "us" or "our"), uses cookies and similar tracking technologies when you visit, access or interact with any websites, web or mobile interfaces, dashboards, portals or applications that link to or reference this Policy (the "Sites"), and any related online services we operate in connection with the Overlayer ecosystem (together with the Sites, the "Services").

This Cookie Policy should be read together with the Terms of Use, the Privacy Policy, the Protocol Risk Disclosure, the Legal Disclaimers and the Regulatory Overview, each of which is incorporated herein by reference. In the event of any inconsistency between this Cookie Policy and the Privacy Policy on matters specific to cookies and similar tracking technologies, this Cookie Policy shall prevail. In all other respects, the Privacy Policy shall apply. Capitalized terms used but not defined in this Cookie Policy have the meanings given to them in the Terms of Use or the Privacy Policy.

By continuing to browse, access or use the Services after being presented with our cookie banner, or by selecting your preferences in our cookie settings tool (where available), or by clicking "I agree", "Accept all", "Allow", or any similar button, you acknowledge that you have read and understood this Cookie Policy and, to the extent required by applicable Laws, agree to our use of cookies and similar technologies as described herein. Where your consent is required by applicable Laws (in particular under EU and UK ePrivacy rules) for non-essential cookies, we will obtain such consent before placing or accessing those cookies on your device.

This Cookie Policy is intended to comply, as applicable, with:

(a) the EU General Data Protection Regulation 2016/679 ("GDPR") and the EU ePrivacy Directive 2002/58/EC as amended ("ePrivacy Directive");

(b) the UK Data Protection Act 2018, the UK GDPR, and the UK Privacy and Electronic Communications Regulations 2003 ("PECR");

(c) the Swiss Federal Act on Data Protection ("FADP");

(d) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA");

(e) the Brazilian General Data Protection Law ("LGPD"); and

(f) other applicable data-protection, ePrivacy, consumer-protection and electronic-communications Laws.

If you do not agree with our use of cookies and similar technologies as described in this Cookie Policy, you may reject non-essential cookies through the cookie banner or settings tool, adjust your browser settings, or cease using the Services. Rejecting or disabling certain categories of cookies may impair the availability or functionality of the Services.


1. Controller, Responsibility and Contact​

For purposes of GDPR, UK GDPR, FADP, CCPA/CPRA, LGPD and analogous Laws, the controller (or "business", as applicable) responsible for the processing of personal data collected through cookies that we place or control via the Services is:

Overlayer Labs Ltd A business company incorporated in the British Virgin Islands Registered office: as disclosed on the Website Email: [email protected] (or, if not operational, [email protected])

Where required under applicable Laws, we may appoint an EU and/or UK representative under Article 27 GDPR or UK GDPR, whose contact details will be published on the Website.

1.2 Role of Third Parties​

Certain cookies are set and controlled by third parties (for example, analytics, infrastructure, security or content providers). Such third parties act as independent controllers (or, in some cases, joint controllers or independent processors) with respect to their own use of personal data and their own cookies. We do not control how such third parties operate their cookies once set. You should review the privacy and cookie policies of those third parties for information about their practices. The Controller is not responsible or liable for the cookie practices of any third party.

1.3 Role of Other Ecosystem Entities​

The Overlayer ecosystem may include the Overlayer Foundation (a foundation company incorporated in the Cayman Islands) and other Ecosystem Entities. Unless expressly stated otherwise in a separate cookie notice issued by such entity, the Foundation and the other Ecosystem Entities do not act as controllers for the cookie-related processing described in this Cookie Policy. Your relationship with the Controller in respect of cookies is not altered by the existence or activities of the Foundation or any other Ecosystem Entity.


2. What Are Cookies and Similar Technologies?​

2.1 Cookies​

"Cookies" are small text files that are placed on, and read from, your device (such as a computer, tablet, mobile phone, or other internet-connected device) when you visit a website. Cookies typically contain information about the website, a unique identifier, the length of time the cookie will remain on your device, and, in some cases, preferences or usage data. Cookies are widely used to make websites work more efficiently, to remember preferences, to support security, to enable analytics and performance measurement, and, in some cases, to support personalization or advertising.

2.2 Similar Technologies​

We may also use technologies that function similarly to cookies, including but not limited to:

(a) local storage and session storage, which store information in your browser's storage area;

(b) pixels, tags, and web beacons, which are tiny graphic files embedded into pages or emails that allow tracking of interactions;

(c) software development kits (SDKs), used in mobile apps or embedded in interfaces to collect and transmit data to third-party services;

(d) device fingerprinting techniques, which combine device and browser characteristics to identify or distinguish devices (to the extent, and only to the extent, we use such techniques);

(e) log files and server logs, which capture technical information about requests made to our servers; and

(f) UTM parameters, referral identifiers, campaign tags and similar URL-embedded identifiers.

For simplicity, in this Cookie Policy we refer to all of the above technologies collectively as "cookies", unless otherwise specified.


3. Why We Use Cookies​

We use cookies to:

(a) operate, maintain and secure the Services;

(b) detect, prevent and respond to fraud, abuse, bots, denial-of-service attacks and other security or integrity threats;

(c) remember your settings and preferences (for example, language, region, cookie-consent preferences, wallet-connection state where technically necessary);

(d) measure and understand how Users interact with the Services in aggregate, to improve performance, debug issues, and develop new features;

(e) comply with applicable Laws, respond to lawful requests and enforce the Terms of Use;

(f) in limited cases, measure the effectiveness of community campaigns, referrals or partner integrations; and

(g) support other purposes consistent with this Cookie Policy and the Privacy Policy.

We do not use cookies to operate a traditional advertising network, to engage in profiling for behavioural advertising, or to build individualized marketing profiles based on your activity across unrelated third-party websites.


4. Categories of Cookies We Use​

We classify cookies into four categories. The specific cookies we use may change over time as we update and improve our systems. The current set of cookies used by the Services can be inspected through the cookie settings tool (where available) or by contacting [email protected].

4.1 Strictly Necessary Cookies​

These cookies are essential for the operation of the Services and cannot be disabled through our systems. They are usually set only in response to actions you take that amount to a request for Services, such as setting your cookie preferences, enabling basic navigation, supporting wallet connection, or maintaining the security of the Services. Examples include cookies that:

(a) store your cookie preferences;

(b) manage basic session or login state (where applicable);

(c) protect the Services against bots, credential stuffing, denial-of-service attacks or other malicious activity;

(d) enable essential navigation, page loading and error handling;

(e) support rate limiting and infrastructure routing; and

(f) enforce geographic or access controls (for example, IP-based geo-blocking for Prohibited Jurisdictions).

You can configure your browser to block or alert you about these cookies, but parts of the Services may then not function properly or at all. Under most applicable Laws (including the EU ePrivacy Directive and UK PECR), strictly necessary cookies do not require your consent, but we nonetheless inform you of their use.

4.2 Performance and Analytics Cookies​

These cookies allow us to measure how Users interact with the Services, to understand which pages and features are most and least used, to identify errors and performance issues, and to improve the Services. They typically collect information in aggregated or pseudonymized form. Examples of purposes include:

(a) counting visits and traffic sources;

(b) measuring session length, bounce rates, click paths and page views;

(c) monitoring error rates, performance metrics and service availability;

(d) analysing trends in the use of particular features, pools, chains, integrations or documentation;

(e) A/B testing and experimentation for UX or reliability improvements; and

(f) detecting unusual patterns that may indicate abuse or technical issues.

These cookies are used only if you consent to them, where consent is required by applicable Laws (in particular, under the EU ePrivacy Directive and UK PECR).

4.3 Functionality Cookies​

These cookies enable the Services to provide enhanced functionality and a more personalized experience. They allow us to remember choices you make — for example, your language, region, theme (dark/light mode), layout preferences, and, where technically necessary, your wallet-connection state across sessions.

If you do not allow these cookies, certain features of the Services may not function properly, and your preferences may be reset on each visit. Some functionality cookies may be set by us; others may be set by third-party providers whose services we integrate into the Services.

These cookies are used only if you consent to them, where consent is required by applicable Laws.

4.4 Targeting Cookies​

We do not aim to operate a traditional advertising or retargeting network. However, in limited cases, we may use targeting cookies to:

(a) track referrals from partners, campaigns, community channels or other traffic sources;

(b) measure the effectiveness of community or marketing campaigns;

(c) associate specific actions taken on the Services with a particular referral source; and

(d) avoid showing you content or messages that are not relevant to your context.

These cookies may be set by us or by third parties. Where required by applicable Laws, targeting cookies will be used only with your consent, and you may withdraw such consent at any time through the cookie settings tool or your browser settings.


5. First-Party and Third-Party Cookies; Session and Persistent Cookies​

5.1 First-Party and Third-Party Cookies​

Cookies set directly by the Controller in respect of the Services are referred to as "first-party cookies". Cookies set by parties other than the Controller are referred to as "third-party cookies". Third-party cookies enable features or functionality provided by the relevant third parties (for example, analytics, security, content delivery, video content, social-media features or other integrations). We do not control how third-party cookies are used once they are set, and any personal data collected by such cookies will be processed in accordance with the privacy and cookie policies of the relevant third parties.

5.2 Session and Persistent Cookies​

Some cookies are "session cookies", which are temporary and are deleted when you close your browser. Others are "persistent cookies", which remain on your device for a specified period or until you delete them. The duration of a persistent cookie depends on its specific purpose and on your browser settings. Where available, the cookie settings tool lists the indicative duration of each cookie category.


Our use of cookies and similar technologies is based on the following legal grounds:

6.1 Strictly Necessary Cookies​

We rely on our legitimate interests (Article 6(1)(f) GDPR and equivalent provisions of UK GDPR) in operating and securing the Services, and, where applicable, on the performance of a contract (Article 6(1)(b) GDPR — the Terms of Use). Under EU and UK ePrivacy rules, strictly necessary cookies are generally exempt from the consent requirement.

6.2 Performance/Analytics, Functionality, and Targeting Cookies​

Where required by applicable Laws (including the EU ePrivacy Directive, UK PECR and equivalent regimes), we use performance/analytics, functionality and targeting cookies only on the basis of your consent (Article 6(1)(a) GDPR). You may provide and withdraw your consent at any time through the cookie banner, the cookie settings tool or by adjusting your browser settings. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to such withdrawal.

Where consent is not legally required in a particular jurisdiction or context, we may rely on our legitimate interests in improving, measuring and securing the Services, subject to conducting the relevant balancing test.

6.3 CCPA/CPRA Considerations​

For California residents, and subject to the conditions of CCPA/CPRA, we will honour verifiable requests to opt out of any "sale" or "sharing" of personal information (as those terms are defined in the CCPA/CPRA). The Controller does not sell personal information for monetary consideration in the ordinary sense of that term and does not share personal information for cross-context behavioural advertising. To the extent any cookie-enabled activity could nevertheless be deemed a "sale" or "sharing" under applicable Laws, we describe such activities and your rights in Section 11.


When you first access the Services (or when we make material changes to our cookie practices), we may display a cookie banner or a consent-management tool. Through this banner or tool, and subject to applicable Laws, you may:

(a) accept all cookies;

(b) reject all non-essential cookies;

(c) manage your preferences by category (strictly necessary, performance/analytics, functionality, targeting); or

(d) access further information about specific cookies.

In jurisdictions where consent is required for non-essential cookies, such cookies will not be set until you have affirmatively provided consent through the banner or tool.

You may change or withdraw your cookie consent at any time by revisiting the cookie settings tool (where available on the Website), by clearing the cookies stored on your device, or by adjusting your browser settings. Withdrawal takes effect for future processing only.

7.3 Browser Settings​

Most modern browsers allow you to:

(a) view which cookies are stored on your device;

(b) accept, reject or delete cookies;

(c) block cookies from specific websites;

(d) block all cookies from being set; and

(e) delete cookies at the end of each browsing session or at any time.

Because the procedures vary between browsers, please refer to your browser's help section or support pages for specific instructions (for example, Chrome, Safari, Firefox, Edge, Brave or mobile equivalents). You can also use private/incognito browsing modes, which typically delete cookies at the end of each session.

If you block or delete cookies, some features of the Services may not function properly.

7.4 Do Not Track and Global Privacy Control​

Your browser may offer a "Do Not Track" (DNT) signal or similar mechanism. Because the DNT standard has not been finalized and industry practice varies, the Services do not, at this time, respond to DNT signals.

In jurisdictions where the Global Privacy Control (GPC) signal is treated as a valid user-enabled opt-out (for example, under CCPA/CPRA and certain U.S. state laws), we will, to the extent technically feasible, honour GPC signals as a request to opt out of any "sale" or "sharing" of personal information. If you use a browser or browser extension that transmits a recognized GPC signal, we will apply that signal to the device and browser from which it is transmitted.

7.5 Mobile and Device-Level Controls​

If you access the Services through a mobile device, you may also have device-level controls that limit cross-app tracking, advertising identifiers or SDK-based collection (for example, Apple's App Tracking Transparency or Google's Ad ID controls). Please refer to your device's settings and the relevant platform's documentation to manage these controls.

7.6 Opt-Out from Specific Providers​

Certain third-party cookie providers offer their own opt-out mechanisms. Where we use such providers, we will endeavour to reference their opt-out options in this Cookie Policy or in the cookie settings tool, to the extent reasonably practicable. For example, opt-out mechanisms are typically offered by:

(a) Google Analytics (via the Google Analytics opt-out browser add-on or account-level controls);

(b) Cloudflare or other security/infrastructure providers (as described in their own privacy documentation); and

(c) other providers listed in the cookie settings tool.

The availability, effectiveness and persistence of third-party opt-outs are outside our control.


8. Third-Party Providers​

We may use the services of third-party providers that set or use cookies in connection with the Services. The specific providers and scope may change over time. The following are illustrative of the categories of third-party providers we may use.

8.1 Security, Performance and Infrastructure Providers​

We may use providers such as Cloudflare (or equivalents) for network security, anti-bot, anti-DDoS, DNS, content delivery, performance optimization and infrastructure purposes. These providers may set strictly necessary cookies for the purposes described in Section 4.1.

8.2 Analytics Providers​

We may use analytics providers such as Google Analytics (or equivalents) to measure aggregated usage of the Services. Where required by applicable Laws, analytics cookies will be placed only with your consent. Data collected through analytics may be processed in countries outside your country of residence (see Section 9). Google Analytics, for example, provides opt-out tools and account-level configurations that we may use to reduce data collection (such as IP anonymization, data-retention limits, or short cookie lifetimes).

8.3 Error and Performance Monitoring​

We may use error-monitoring, observability or performance-monitoring providers that set cookies or similar identifiers to correlate error events with User sessions, to assist in debugging and reliability.

8.4 Other Providers​

We may integrate additional providers (for example, tag managers, documentation hosting, feature-flag platforms, community or feedback tools, wallet-connect infrastructure) that may set cookies in the course of providing their services. Where material, such providers will be disclosed in the cookie settings tool or in an updated version of this Cookie Policy.

8.5 No Responsibility for Third-Party Practices​

Third parties act independently with respect to their own cookies and data processing. We do not control, operate, audit or endorse their practices, and, to the maximum extent permitted by applicable Laws, we are not responsible or liable for them. You should review the privacy and cookie policies of each relevant third party before using, or as a condition of continuing to use, the Services.


9. International Transfers​

Because the Controller is incorporated in the British Virgin Islands and relies on global infrastructure and service providers, personal data processed through cookies may be transferred to, stored in, accessed from or otherwise processed in countries outside your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction.

Where GDPR, UK GDPR or FADP applies, and where such transfers occur to a country that has not been the subject of an adequacy decision, we rely on one or more safeguards, including Standard Contractual Clauses approved by the European Commission (or UK/Swiss equivalents), binding corporate rules, or applicable derogations. For further information about the safeguards applicable to cookie-related transfers, please see Section 9 of the Privacy Policy or contact [email protected].


10. Retention and Duration of Cookies​

10.1 Duration​

Cookies are retained on your device for the period necessary to achieve their purpose, subject to applicable Laws. Session cookies expire when you close your browser. Persistent cookies remain on your device until they reach their expiration date or until you delete them. Indicative durations for the principal categories of cookies we use are disclosed in the cookie settings tool (where available).

10.2 Retention of Data Derived from Cookies​

Personal data derived from cookies (for example, analytics records, security telemetry or fraud-prevention logs) is retained in accordance with the retention principles set out in Section 10 of the Privacy Policy. In general, we retain such data only for as long as reasonably necessary to fulfil the purposes for which it was collected, to meet legal obligations, to protect our rights, and to address security, fraud or technical matters.

10.3 Deletion​

When personal data derived from cookies is no longer required, we will delete it, destroy it, or irreversibly anonymize it, except to the extent we are required or permitted by Law to retain it (for example, for the purposes of demonstrating compliance, defending legal claims, or for backup integrity).


11. Cookies and Personal Data​

11.1 Personal Data​

Some cookies collect information that may qualify as personal data under applicable data-protection Laws, including IP addresses (even in truncated or pseudonymized form), device identifiers, and certain usage data that, alone or in combination with other information, relates to an identifiable individual.

11.2 Applicable Privacy Framework​

Where cookies collect personal data:

(a) the Privacy Policy explains in more detail how we use such personal data, for which purposes, on which legal bases, with which recipients, and subject to which safeguards;

(b) we will process such personal data in accordance with the Privacy Policy and applicable data-protection Laws; and

(c) you may exercise your rights in respect of such personal data in accordance with Section 12 of the Privacy Policy.

11.3 CCPA/CPRA Rights​

If you are a resident of California, you may have the right, subject to applicable conditions and limitations, to: (i) know the categories and specific pieces of personal information collected through cookies; (ii) request deletion of such personal information; (iii) request correction; (iv) opt out of any "sale" or "sharing" (including in response to a Global Privacy Control signal, where technically feasible); and (v) not be discriminated against for exercising your rights. Please see Section 12.2 of the Privacy Policy for details on how to exercise these rights.

11.4 Sensitive Information​

We do not intentionally use cookies to collect "special category" or "sensitive" personal data under GDPR, UK GDPR, CCPA/CPRA or analogous Laws.


12. No Profile Building for Behavioural Advertising​

The Controller does not use cookies to build an individualized behavioural profile of you for the purposes of cross-context behavioural advertising, micro-targeted marketing, or the sale of personal information to advertisers or data brokers. To the extent our cookie-related activities could nevertheless be construed as falling within the CCPA/CPRA definition of "sale" or "sharing", you may exercise the opt-out rights described in Section 7.4 and Section 11.3.


13. Specific Considerations for Non-Custodial Services​

13.1 Wallet Connection​

Certain features of the Services allow you to connect a self-custodial Wallet (such as MetaMask). Wallet connection is typically managed by third-party libraries and Wallet providers, which may use their own cookies, local storage or similar technologies. The Controller has no control over or access to your Wallet, private keys, seed phrases, signing credentials or the Digital Assets held therein. Your relationship with the Wallet provider is governed solely by that provider's own terms and privacy practices.

13.2 Public Blockchain Observability​

Once you sign and broadcast a transaction using your Wallet, the transaction (and its metadata) is recorded on a public blockchain and is visible to anyone, regardless of cookies or our Services. Cookies do not affect the public, immutable nature of on-chain data. For further information, please see Sections 10.5 and 15 of the Privacy Policy.

13.3 Independent Front-Ends and Third-Party Interfaces​

The Protocol is public code, and any person or entity may build and operate independent front-ends, interfaces or tools that interact with it. Such Independent Tools (as defined in the Terms of Use) are outside the control of the Controller and may use their own cookies and tracking technologies. This Cookie Policy applies only to the Services operated by or on behalf of the Controller.


14. Children​

The Services are not directed to, and are not intended for, children under the age of 18 (or the age of majority in their jurisdiction, if higher). The Controller does not knowingly use cookies to collect personal data from children under the age of 18. If you believe we may have inadvertently used cookies to collect personal data from a child under 18, please contact [email protected] so that we can take appropriate steps to delete such data.


The Controller may update this Cookie Policy from time to time to reflect changes in the cookies and similar technologies we use, in the Services, in our business, or in applicable Laws and guidance. When we do so, we will update the "Last Revised" date at the top of this Cookie Policy and may, where appropriate, provide additional notice (for example, by displaying a banner on the Website or by triggering a renewed display of the cookie banner) where required by applicable Laws.

Your continued use of the Services after the effective date of any updated Cookie Policy constitutes your acknowledgement of the updated Policy, to the extent permitted by applicable Laws. Where your consent is required for non-essential cookies, we will request renewed consent in connection with material changes.

We encourage you to review this Cookie Policy periodically to stay informed about our use of cookies and similar technologies.


16. Disclaimers and Limitations of Liability​

To the maximum extent permitted by applicable Laws, and without prejudice to the Controller's obligations under applicable data-protection and ePrivacy Laws:

(a) the Controller provides this Cookie Policy on an informational basis and does not guarantee that the Services, the cookie banner, the cookie settings tool, opt-out mechanisms or any third-party control will be uninterrupted, effective, complete, accurate, timely or free of defects;

(b) the Controller is not responsible or liable for the cookie or tracking practices of any third party, including third-party analytics, security, infrastructure, content, social-media, Wallet or Third-Party Service provider, or for any effect on your devices, browsers or accounts resulting from the use of such third-party cookies;

(c) the Controller does not warrant the operation, durability, security or persistence of any third-party opt-out mechanism or Do Not Track / Global Privacy Control signal, and shall not be liable for their failure, change or discontinuation;

(d) the Controller's aggregate liability to you for any matter arising out of or in connection with this Cookie Policy, our use of cookies, or our processing of cookie-related personal data shall, to the extent not prohibited by applicable Law, be subject to the limitations set out in Section 12 of the Terms of Use, including the aggregate liability cap; and

(e) the Operator Parties (as defined in the Terms of Use) are intended third-party beneficiaries of this Cookie Policy to the extent relevant, and may enforce its provisions directly.

This Section 16 does not limit or exclude any liability that cannot lawfully be limited or excluded under applicable data-protection, ePrivacy or consumer-protection Laws.


17. Relationship with Other Policies​

This Cookie Policy forms part of, and must be read together with, the following documents, each of which is available on the Website and is updated from time to time:

(a) the Terms of Use, which govern your broader relationship with the Controller, including dispute resolution, liability caps, class-action waivers and indemnification;

(b) the Privacy Policy, which describes in detail our processing of personal data, your rights and our legal bases;

(c) the Protocol Risk Disclosure, which describes the material risks of interacting with the Protocol, Overlaid Assets, the OVER token and Third-Party Protocols;

(d) the Legal Disclaimers, which set out general disclaimers applicable to the Services; and

(e) the Regulatory Overview, which describes the intended regulatory positioning of the Protocol and Overlaid Assets.

In the event of any inconsistency between this Cookie Policy and any of the foregoing documents on matters specific to cookies and similar tracking technologies, this Cookie Policy shall prevail. In all other respects, the Terms of Use shall prevail as to non-privacy matters, and the Privacy Policy shall prevail as to privacy matters.


18. Complaints​

18.1 Complaints to the Controller​

If you have any question, concern or complaint regarding our use of cookies, please contact us at [email protected]. We will investigate your complaint and respond within a reasonable period.

18.2 Complaints to Supervisory Authorities​

Without prejudice to any other remedy, you have the right to lodge a complaint with a competent supervisory authority in your jurisdiction, including, where applicable, the data-protection authority of an EU Member State, the UK Information Commissioner's Office (ICO), the Swiss Federal Data Protection and Information Commissioner (FDPIC), the California Privacy Protection Agency (CPPA), the Brazilian Autoridade Nacional de Proteção de Dados (ANPD), or the relevant Canadian privacy commissioner.


19. Contact​

If you have any questions, concerns or requests regarding this Cookie Policy or our use of cookies and similar technologies, you may contact us at:

Email (primary): [email protected]

Email (secondary): [email protected]

Mailing Address: Overlayer Labs Ltd, as disclosed on the Website.


This Cookie Policy is designed to operate in conjunction with the Terms of Use, the Privacy Policy, the Protocol Risk Disclosure, the Legal Disclaimers and the Regulatory Overview, each as made available through the Website and updated from time to time.